Skip to content
Security & Trust

DARPA selects Xint to research AI security checks for military messaging apps

Xint's CTO: in-house option is a work in progress, as it won't be able to use the latest OpenAI and Anthropic models

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
DARPA selects Xint to research AI security checks for military messaging apps

AI-generated image for WebPulse. About our images

Key finding

AIxCC competition size: $29.5 million (Source: SecurityWeek, reporting on DARPA's AI Cyber Challenge (September 29, 2026))

Model quality is one question when weighing AI code review. Where your code has to go is another. A remark from the CTO of Xint, the firm DARPA just selected, points to a question worth asking before you buy.

What DARPA chose to do

SecurityWeek reported that DARPA selected Xint to research autonomous AI application security. The work is deep analysis of messaging apps used across the Department of War. Some of those apps are built inside the department and some outside it.

Xint emerged within Theori. SecurityWeek says DARPA's pick followed Xint's showing in the AI Cyber Challenge (AIxCC), where it was one of three winners. That contest ran for two years and had a $29.5 million pool.

Xint is now tasked with analysing source code. SecurityWeek names messaging apps such as Signal and open source projects as examples of that code. The report does not say which apps DARPA will test.

The second job covers compiled binaries, meaning finished programs with no readable source. Xint launched a new service for this in September 2026. SecurityWeek describes it as a way to gauge supply chain risk in such code. The code may run inside AI agents, in software installed on a customer's own servers, in hardware appliances, or in background network services.

$29.5 million
AIxCC competition size
Source: SecurityWeek, reporting on DARPA's AI Cyber Challenge (September 29, 2026)
3
Winners of the AIxCC
Source: SecurityWeek (September 29, 2026)

How the system works

Andrew Wesie, Xint's CTO and co-founder, told SecurityWeek the product is "really just a harness and a workflow" around the latest large language models. A harness is the software wrapped around an AI model. It shapes what the model sees and what happens to its answers.

The report does not describe Xint's internals. It does describe the outcome Wesie claims. The system examines all the source code involved and reverse engineers binaries when needed. It then investigates vulnerabilities across the attack surface and ranks them by how accessible they are to an attacker. Finally, it generates patches for those that could be useful to attackers.

For a message sent from Android, Wesie said Xint would look at the app, the Linux kernel and the Android components between them. Reverse engineering means working backward from a compiled program to understand how it behaves.

These are Xint's own descriptions of the product. SecurityWeek did not report test results.

Why messaging apps are a hard target

Wesie argues that messaging apps are unusual. An attacker needs only read-only access to compromise the whole point of the app. He also pointed to third-party software kits and libraries embedded in these apps. Even minor leaks, he said, may expose a user's location or other personal information, often without the user or developer knowing.

This is a supply chain problem as much as a coding problem. The app you buy contains code you did not write and may not have reviewed. Reviewing across those layers is what Xint says its system is built to do.

One vendor's limit: in-house deployment

Xint offers its service as SaaS, meaning software run as a hosted service. A developer runs code through it before release, then runs regular scans to catch flaws introduced later.

Wesie acknowledged that some enterprises want everything inside their own data centre because they do not want source code to leave. Running Xint that way is "still a work in progress", he said. His stated reason was mainly that Xint would not be able to use the latest OpenAI and Anthropic models.

SecurityWeek's quote is cut off at that point. The full reason and the full extent of the limit are not in the report. The source gives no timeline. It says nothing about how Xint's in-house option performs, or about other vendors' tools.

So this is one data point about one product. It does suggest a question worth asking any vendor: does the on-premises version use the same models as the hosted one?

What is not yet known

The report gives no vulnerability counts, no contract value and no timeline. It says DARPA selected Xint to research the approach. It does not say any app has been secured. DARPA's own site, as provided, carried nothing on this award, so the details rest on SecurityWeek's interview with Xint.

Questions for your security team

If your team is weighing AI code review, put these questions to vendors and to yourselves.

First, which of our code can legally and contractually leave our environment? Second, does the vendor's on-premises option use the same models as its hosted service? Third, who reviews AI-generated patches before they ship? Fourth, do we know which third-party SDKs sit inside the apps we buy or build?

The lesson here is that the model is only half the decision. The other half is where your most sensitive code must travel to be reviewed. Xint's remark points to a question worth asking before you sign.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: DARPA (Defense Advanced Research Projects Agency).

Share this insight